VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2015-4960MedJan 17, 2016
    risk 0.27cvss 4.1epss 0.01

    IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

  • CVE-2025-14684MedMar 25, 2026
    risk 0.26cvss 4.0epss 0.00

    IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

  • CVE-2025-12755MedFeb 17, 2026
    risk 0.26cvss 4.0epss 0.00

    IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2, CD, and LTS 9.3.x–9.4.x releases) contain a vulnerability where log messages are not properly neutralized before being written to log files. This…

  • CVE-2025-36082MedSep 15, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system.

  • CVE-2025-1348MedJun 18, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.

  • CVE-2025-1334MedJun 3, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2023-43035MedApr 10, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2024-22315MedJan 28, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.

  • CVE-2024-22349MedJan 20, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2024-51462MedJan 17, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.

  • CVE-2022-35640MedJul 16, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive information when a detailed technical error message is returned. IBM X-Force ID: 230933.

  • CVE-2022-38383MedJun 28, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.

  • CVE-2024-22338MedMay 31, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: 279978.

  • CVE-2022-43841MedMay 30, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 239078.

  • CVE-2024-22343MedMay 14, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 280190.

  • CVE-2023-46181MedMar 15, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 269686.

  • CVE-2023-27545MedFeb 29, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 248947.

  • CVE-2023-50306MedFeb 20, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.

  • CVE-2023-50951MedFeb 17, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.

  • CVE-2023-47140MedJan 8, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.

  • CVE-2023-47704MedDec 20, 2023
    risk 0.26cvss 4.0epss 0.01

    IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220.

  • CVE-2022-34355MedOct 6, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a user that could be used in further attacks against the system. IBM X-Force ID: 230498.

  • CVE-2022-22447MedOct 4, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclose unintended information. IBM X-Force ID: 224648.

  • CVE-2023-22593MedJun 27, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redis container which may provide elevated privileges. IBM X-Force ID: 244074.

  • CVE-2022-38707MedMay 5, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.

  • CVE-2020-4556MedMar 15, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM Financial Transaction Manager for High Value Payments for Multi-Platform 3.2.0 through 3.2.10 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 183329.

  • CVE-2022-42436MedFeb 12, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM MQ 8.0.0, 9.0.0, 9.1.0, 9.2.0, 9.3.0 Managed File Transfer could allow a local user to obtain sensitive information from diagnostic files. IBM X-Force ID: 238206.

  • CVE-2023-23469MedFeb 1, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM ICP4A - Automation Decision Services 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 244504.

  • CVE-2023-22592MedJan 18, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permission settings. IBM X-Force ID: 244073.

  • CVE-2022-34354MedNov 16, 2022
    risk 0.26cvss 4.0epss 0.00

    IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424.

  • CVE-2022-34314MedNov 14, 2022
    risk 0.26cvss 4.0epss 0.00

    IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings. IBM X-Force ID: 229450.

  • CVE-2022-34312MedNov 14, 2022
    risk 0.26cvss 4.0epss 0.00

    IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 229447.

  • CVE-2018-1623MedApr 2, 2019
    risk 0.26cvss 4.0epss 0.00

    IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408.

  • CVE-2018-1962MedFeb 4, 2019
    risk 0.26cvss 4.0epss 0.00

    IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 153658.

  • CVE-2018-1993MedJan 8, 2019
    risk 0.26cvss 4.0epss 0.00

    IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.

  • CVE-2018-1480MedDec 12, 2018
    risk 0.26cvss 4.0epss 0.01

    IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerability also existed attackers may be able to get the cookie values via malicious JavaScript and then…

  • CVE-2018-1957MedDec 10, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.

  • CVE-2018-1505MedDec 6, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 141413.

  • CVE-2018-1568MedDec 5, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 143118.

  • CVE-2017-1418MedNov 26, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM…

  • CVE-2016-9749MedNov 9, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass security due to lack of input validation. IBM X-Force ID: 120206.

  • CVE-2016-0234MedAug 30, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.

  • CVE-2018-1655MedJun 22, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.

  • CVE-2017-1733MedApr 4, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.

  • CVE-2017-1756MedMar 30, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.

  • CVE-2017-1654MedMar 2, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.

  • CVE-2017-1773MedJan 31, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.

  • CVE-2017-1783MedJan 29, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication. IBM X-Force ID: 136857.

  • CVE-2016-0382MedMay 3, 2017
    risk 0.26cvss 4.0epss 0.00

    The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be accidentally captured and exposed by network infrastructure components such as IIS. IBM X-Force ID: 112356.

  • CVE-2016-6097MedFeb 7, 2017
    risk 0.26cvss 4.0epss 0.00

    IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.

Page 115 of 177